Техническая информация
- '<SYSTEM32>\taskkill.exe' /F /IM wscript.exe /T
- <SYSTEM32>\wscript.exe
- %TEMP%\1.tmp\2.bat
- %TEMP%\hardware.vbs
- %TEMP%\wirus.vbs
- 'localhost':1038
- 'localhost':1040
- 'localhost':1041
- 'go##le.pl':443
- 'localhost':1043
- 'localhost':1044
- 'localhost':1047
- 'localhost':1048
- 'localhost':1049
- 'localhost':1050
- 'localhost':1053
- 'yo##ube.com':443
- DNS ASK www.go##le.pl
- DNS ASK yo##ube.com
- ClassName: 'RegEdit_RegEdit' WindowName: ''
- ClassName: '' WindowName: ''
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- '<SYSTEM32>\wscript.exe' "%TEMP%\hardware.vbs"
- '<SYSTEM32>\wscript.exe' "%TEMP%\wirus.vbs"
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\1.tmp\2.bat" <Полный путь к файлу>"
- '<SYSTEM32>\cacls.exe' "<SYSTEM32>\config\system"
- '%WINDIR%\regedit.exe' /s %HOMEPATH%\Downloads\G3T4Kair\menadzer.reg
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' https://www.go##le.pl/?gw##############################
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' https://www.go##le.pl/?gw############################################
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' https://www.go##le.pl/?gw############################
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' https://www.go##le.pl/?gw########################
- '%ProgramFiles%\Internet Explorer\IEXPLORE.EXE' https://youtube.com/c/hardwareexplained